Skip to content

Commit baba98b

Browse files
committed
Add security disclosure info
1 parent 6c2e3be commit baba98b

File tree

1 file changed

+17
-0
lines changed

1 file changed

+17
-0
lines changed

SECURITY.md

+17
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
# Security Policy
2+
3+
Last Updated: 2020-03-21
4+
5+
## Reporting a Vulnerability
6+
7+
The recommended mechanism for reporting possible security vulnerabilities follows
8+
so-called "Coordinated Disclosure Plan" (see [definition of DCP](https://vuls.cert.org/confluence/display/Wiki/Coordinated+Vulnerability+Disclosure+Guidance)
9+
for general idea). The first step is to file a [Tidelift security contact](https://tidelift.com/security):
10+
Tidelift will route all reports via their system to maintainers of relevant package(s), and start the
11+
process that will evaluate concern and issue possible fixes, send update notices and so on.
12+
Note that you do not need to be a Tidelift subscriber to file a security contact.
13+
14+
Alternatively you may also report possible vulnerabilities to `info` at fasterxml dot com
15+
mailing address. Note that filing an issue to go with report is fine, but if you do that please
16+
DO NOT include details of security problem in the issue but only in email contact.
17+
This is important to give us time to provide a patch, if necessary, for the problem.

0 commit comments

Comments
 (0)